Fortinet patches 8 bugs, worst is a FortiWeb login bypass

Fortinet published eight security advisories on August 12, 2026, and the one to read first affects FortiWeb, the company's web application firewall. Tracked as CVE-2026-26035 and scored 8.8, it lets a remote attacker with no credentials log into the FortiWeb GUI or CLI using a random username and password.

The important caveat is configuration. Fortinet says the flaw only applies where remote RADIUS administrator authentication has been set up with specific, non default settings, namely the Wildcard option on a remote type admin account. The company found the bug in its own audit rather than in the wild. Affected builds are FortiWeb 8.0.0 through 8.0.2 (fixed in 8.0.3), 7.6.0 through 7.6.6 (fixed in 7.6.7), 7.4.0 through 7.4.11 (fixed in 7.4.12) and 7.2.0 through 7.2.12 (fixed in 7.2.13). If you cannot patch straight away, the Fortinet advisory says to open the remote type administrator account under System, Administrators and disable Wildcard.

The rest of the batch

The other seven, in descending order of severity, are all rated Medium or High and none of them is listed as known exploited:

What you should do

Patch order should follow exposure rather than score alone. The FortiWeb admin bypass matters most to anyone running remote RADIUS administrator accounts, and it is worth checking whether the Wildcard option is on before assuming you are out of scope. The FortiManager issue is the quietest of the serious ones and potentially the most damaging, since impersonating a managed firewall puts an attacker inside a trust relationship rather than at the perimeter. For the two FortiWeb and FortiOS proxy issues, Fortinet has shipped virtual patches (FG-VD-10009598.0day in FMWP database update 26.071 and FG-VD-10009617.0day in update 26.073) for customers who need cover before a version upgrade.

None of these is under attack today, but Fortinet appliances rarely stay quiet for long. CISA added a FortiOS flaw to its Known Exploited Vulnerabilities catalog in July, and attackers were hijacking FortiSandbox analysis servers through unauthenticated API flaws in June. Edge devices get scanned within days of an advisory, so treat the published version tables as a deadline.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions